An AI product is a software product Art. 3(1), Recital 12
The CRA does not carve AI out. A product with digital elements is software or hardware plus its remote data processing solutions, and an AI tool is software. A downloadable or installable AI application, model runtime, or agent supplied to EU users in the course of business is in scope like any other software product.
The hosted-versus-downloadable distinction matters here as it does for SaaS. A purely browser-based or API-only AI service with nothing installed is closer to an online service, while shipping downloadable weights, a desktop client, or tools puts a product in scope. Assess what the customer actually receives.
Judgment call: The line between a hosted AI service and a downloadable AI product turns on what is installed, the same functional judgment the CRA applies to other online services.
Article 12: how the CRA meets the AI Act Art. 12(1), Art. 12(2)
Article 12 addresses products with digital elements that fall within CRA scope and are classified as high-risk AI systems under Article 6 of Regulation (EU) 2024/1689 (the AI Act). Such products are deemed to comply with the cybersecurity requirements in Article 15 of the AI Act where they fulfil the essential requirements in Part I of Annex I, their processes comply with Part II of Annex I, and the level of protection required under Article 15 of the AI Act is demonstrated in the EU declaration of conformity issued under the CRA.
For those products and requirements, the conformity assessment procedure in Article 43 of the AI Act applies. Notified bodies competent under the AI Act are also competent to check conformity with Annex I of the CRA, provided they meet the CRA notification requirements.
The carve-out for important and critical AI products Art. 12(3), Art. 12(4)
Article 12 includes a derogation. Important products under Annex III that are subject to the stricter conformity procedures, and critical products under Annex IV that need a European cybersecurity certificate or the stricter procedures, which are also high-risk AI systems to which the AI Act's internal-control conformity route applies, are instead subject to the CRA conformity procedures for the essential cybersecurity requirements.
In short, the AI Act route is the default for high-risk AI systems that are in CRA scope, but the CRA route is preserved for the important and critical categories so the level of assurance is not reduced. Manufacturers of these products may also take part in the AI regulatory sandboxes under the AI Act.
Obligations and the dates Art. 13, Art. 14, Art. 71(2)
For an in-scope AI product you still meet the CRA essential cybersecurity requirements, handle vulnerabilities (including a coordinated vulnerability disclosure policy), draw up technical documentation, and complete the applicable conformity route (the AI Act procedure, or the CRA procedure where the carve-out applies). Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.